Industry executives and experts share their predictions for 2024. Read them in this 16th annual VMblog.com series exclusive.
Examining What’s Ahead for Data Security in 2024
By Joe Regensburger, VP of Research & AI SME at Immuta
2023 was a banner year for AI advancements. From the rapid adoption of ChatGPT to the creation of AI tools that can create art, music, teach classes and so much more, it seems like we’ve found a way to augment nearly every aspect of our working and social lives with technology. It’s an exciting time to be in the tech space, but it’s also a moment in time that requires data practitioners and security professionals to steward ethical AI and data practices. As we move forward in AI, we must continue to keep customer data access and security as a top priority. AI isn’t going anywhere so we need to consider how it will impact organizations and data in the upcoming year.
One of the biggest questions about AI going into 2024 is centered around liability. The EU’s AI Act is proposing restrictions on the purposes for which AI can be employed, placing more scrutiny on high-risk applications, but President Biden’s October 30th executive order concerning AI took a slightly different tune, focusing on the vetting and reviewing of models and imposing restrictions and standards based on that. On both sides, liability and indemnity remain murky. In 2024, as these regulations fall into place, industry leaders will begin to get more clarity around who is liable for what and AI insurance will emerge as regulators and industry leaders look to harden the vetting and reviewal process, both in production and in development.
My colleagues and I also spent some time reveling in the last year of advancements in AI and data security and I wanted to share some of their perspectives on what we think data practitioners and technology leaders can expect in the space for 2024.
- Mike Scott, CISO at Immuta
New AI tools will require clear policies and increased education from the top down
“Gartner predicts that IT spending will increase more than 70% over the next year. In addition to expanding current solutions, this will likely mean new tools, software, technology integrations, etc., and a lot of it will be powered by artificial intelligence (AI). Organizations have to continue to embrace new technology to remain competitive and relevant in today’s economic landscape. Still, the introduction and integration of AI-based solutions create complexities for security teams, who will have more to manage and oversee than ever before.
To support the inevitability of AI, organizations will need to do two things. First, they will need to implement policies and processes around AI in general, and these integrations, or the speed at which they can innovate, will be impacted. Second, there will be a need for a significant amount of education from the top down around the difference between AI, machine learning (ML), and large language models (LLMs) to ensure teams are aware of what risks exist and when company policies are relevant. The democratization of AI means the technology is being used by employees who are not as technologically savvy. There will likely be confusion around how to write and apply new policies to these new tools, given the broad user base.”
Data visibility will help to drive regulatory compliance across organizations
“As privacy laws continue to evolve and new regulations are introduced, it’s becoming much more challenging to determine which regulations apply to you, which to apply to your data set, and how to adhere to each regulation. Despite the proliferation of policies, most companies still don’t have a dedicated privacy team or leader responsible for this. Looking ahead, having the ability to easily look across your data and understand what kind of data you have, where it’s at, and what policies apply to that will be incredibly important to ensure compliance.”
Continued transition to the cloud creates more third-party risk
“Third-party risk will evolve as a big data-security-related challenge in the coming year as organizations of all sizes continue their transition to the cloud. It’s clear teams can’t accomplish the same amount of work at scale with on-prem solutions as they can in the cloud, but with this transition comes a pressing need to understand the risks of integrating with a third party and monitor that third party on an ongoing basis. Organizations tend to want to move quickly, but it’s important that business leaders take the time to evaluate and compare the security capabilities of these vendors to ensure they are not introducing more risk to their data.”
- Claude Zwicker, Senior Product Manager & Data Mesh SME, Immuta
Data mesh to become more business-driven vs IT-driven
“As AI continues to increase the appetite for more data distributed everywhere, business professionals will continue to explore conceptual solutions like data mesh that enable data democratization. But as money gets tighter and investments become more targeted, IT leaders must shift the way they look at data mesh adoption to turn it from a buzz into a reality, focusing more on the milestones they can hit to show business value, rather than being solely fixated on reaching the perfect state of implementation.”
With the rapid onset of AI solutions and ongoing push to migrate data to the cloud, in 2024 data leaders will prioritize data security, agility, and visibility. This will require solutions that provide data protection and the flexibility to use data to drive value for organizations.
##
ABOUT THE AUTHOR
Joe Regensburger is the Vice President of Research at Immuta, a leader in data security that enables organizations to unlock value from their cloud data by protecting it and providing secure access. At Immuta, Joe leads research and development efforts focusing on Algorithm Development, Data Privacy, Data Discovery and Classification, Data Security, and Risk Analysis. Prior to joining Immuta in 2017, Joe served positions as a Chief Scientist and Principal Research Statistician. Joe earned a PhD in Physics from The Ohio State University with a focus on Experimental High Energy Physics.





